Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Windows Vulnerability Blinds EDR, Bypasses AMSI, AppLocker, Sysmon
July 20, 2026
Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data
July 20, 2026
Critical wp2shell RCE Vulnerability Under Active Exploitation
July 20, 2026
Home/CyberSecurity News/Threat Actors Sell Stolen Starbucks Customer Data on Hacker Forums
CyberSecurity News

Threat Actors Sell Stolen Starbucks Customer Data on Hacker Forums

Key Takeaways A threat actor is allegedly selling a database containing 176 million Starbucks customer records on a cybercrime forum. The purported data includes personal details, loyalty program...

Jennifer sherman
Jennifer sherman
July 20, 2026 3 Min Read
5 0

Key Takeaways

  • A threat actor is allegedly selling a database containing 176 million Starbucks customer records on a cybercrime forum.
  • The purported data includes personal details, loyalty program information, and password hashes, posing significant privacy and fraud risks.
  • Starbucks has not confirmed the incident, and the authenticity of the data remains unverified.
  • Customers are advised to monitor accounts, use unique strong passwords, and be wary of phishing attempts.

A significant cache of Starbucks customer data, purportedly totaling 176 million unique user records, is being offered for sale on a prominent cybercrime forum. The seller, operating under the alias “anes2010,” claims the database was extracted in June 2026 and includes a wide array of sensitive information.

Table Of Content

  • Key Takeaways
  • Alleged Starbucks Database Leak Details
  • What You Should Do

As of this report, Starbucks has not issued any public statement acknowledging or confirming the alleged security breach. Consequently, the claims made by the threat actor, including the legitimacy of the breach and the contents of the dataset, remain unverified and should be regarded as unconfirmed.

The alleged Starbucks database is listed for $400, with the threat actor reportedly providing sample records to substantiate the sale. While the sharing of samples is a common tactic employed by cybercriminals to lend credibility to their claims, these samples alone do not definitively prove the authenticity, currency, or direct origin of the entire dataset from the named organization.

According to a post shared by the threat intelligence account Intel and Breaches, the forum listing details that the alleged database encompasses email addresses, usernames, hashed passwords, geographical data (country and city), account creation dates, last activity timestamps, account status, and email verification status.

Alleged Starbucks Database Leak Details

The threat actor further asserts that the database contains highly sensitive information related to Starbucks Card details, including balances, auto-reload settings, preferred store locations, and beverage preferences. Additional alleged data points include customer birthdays, Starbucks Rewards points, lifetime Stars accumulated, total spending figures, and currency information.

Should these claims prove accurate, the amalgamation of account, loyalty program, and personal identifying information could expose affected customers to substantial privacy violations and elevated risks of financial fraud.

The presence of password hashes in the alleged dataset does not automatically imply plaintext password exposure. The actual risk level is contingent upon several critical factors: the specific password-hashing algorithm employed, its configuration, the use of unique salts for each hash, and the overall security controls implemented by Starbucks. Outdated or weak hashing mechanisms could potentially allow attackers to perform offline password cracking attempts, while the combination of email addresses and detailed loyalty program data could facilitate highly sophisticated and targeted phishing campaigns.

Attackers could leverage this information to craft convincing fraudulent communications regarding reward points, account suspensions, Starbucks Card balances, payment updates, changes to auto-reload settings, or account verification requests. The ultimate goal of such campaigns would be to trick recipients into divulging their credentials or payment information.

Customers who practice password reuse across multiple online services face an amplified risk. If the alleged records are validated and password hashes are subsequently compromised or cracked, these reused credentials could be exploited in “credential stuffing” attacks, where attackers attempt to use the stolen username-and-password combinations against other email, banking, retail, and social media accounts.

What You Should Do

  • Monitor Account Activity: Regularly check your Starbucks Card balance, rewards activity, stored payment methods, and account profile for any unauthorized or suspicious changes.
  • Be Wary of Phishing: Exercise extreme caution with unexpected emails, SMS messages, or calls claiming to be from Starbucks, especially those that demand urgent action.
  • Avoid Suspicious Links: Do not click on links embedded in unsolicited messages. Instead, access your Starbucks account directly via the official Starbucks mobile app or by typing the company’s official website URL into your browser.
  • Use Strong, Unique Passwords: Create a unique, complex password for your Starbucks account that is not reused on any other online service. Consider using a reputable password manager.
  • Enable Multi-Factor Authentication (MFA): If available, enable multi-factor authentication on your Starbucks account for an added layer of security.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachHackerphishingSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical ServiceNow RCE Vulnerability CVE-2023-46816 Gets Public Exploit

Next Post

GoldenEyeDog Hackers Breach DigiCert, Steal Code-Signing Certificates

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Ends OneDrive Sync App Updates for Windows 10
July 20, 2026
Microsoft Patches Dell USB-C Bug With Out-of-Band Update KB5121767
July 20, 2026
LG Monitors Silently Install Adware on Windows via ScreenX App
July 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us